CVE-2024-52961
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.
Vendor
Product
CWE
Yayın Tarihi
2025-03-11 15:15:42
Güncelleme
2026-01-14 15:15:55
Source Identifier
psirt@fortinet.com
KEV Date Added
-